If crypto can be broken, it will be broken, whether that's by state actors or by some kid in Mongolia who wants to make a quick buck by ransoming all your files.
If crypto can be broken, it will be broken, whether that's by state actors or by some kid in Mongolia who wants to make a quick buck by ransoming all your files.
What you've just expressed is one of those fascinating pieces of mental junk that clutters up social groups, a political desire that's so strongly held you've managed to rationalise to yourself that it's a fact and not a personal desire at all. But it's still not a fact.
It is trivial to use cryptography in ways that yield some sort of balance between personal privacy and the needs of the state. In fact it's almost the default:
• Client-to-server encryption with central message routing is "unbreakable" against neighbours, friends, your employer (when not using their equipment) and most importantly criminals, but is easily accessed by any police officer who can serve a warrant on the provider.
• Disk encryption enforced by secure hardware like iOS, Android, BitLocker etc can easily be given a backdoor by the manufacturers. It's only a few pages of extra code at most.
And that's about it for "mainstream use of crypto up to about 3 years ago" right? It's only since Apple and Facebook started refusing to unlock devices and claiming (wrongly) they have end-to-end encrypted their service so they can no longer comply with warrants that this situation has changed.
That's not even including other techniques like key escrow, the dual-EC RNG that the NSA was pushing (with the interesting fillip that it's got a cryptographically strong "unbreakable" backdoor!) and a whole host of other tricks that aren't really used much (we think).
PHK's article even spells this out for you - Kazakhstan breaks the supposedly unbreakable TLS by simply insisting everyone configure their computer to allow them that ability, a feature well intended by the TLS designers.
The truth is that there's a vast middle ground between "unbreakable crypto" and "effectively no crypto at all" and it is in that middle ground the virtually all services we use today sit. Enough crypto is used to keep out ordinary criminals and snoops, but not enough is used to keep out determined governments with jurisdiction. The point the author is making is that attempting to pursue the ideal of unbreakable crypto (a) won't work and (b) will actually end up making privacy worse for everyone.
A backdoored crypto system is a broken crypto system.
Sidenote, why do people call a second key a backdoor? To me, backdoor suggests exploit, not used-as-designed.
You can repeat "a backdoored system is no system" mantra to yourself if you like, but there are a LOT of threats that aren't governments and those are the ones people tend to care about the most.
But that's the point: we've seen that this balance doesn't exist, because if the service providers have access to the plaintext, the State will not contain itself to issuing case-by-case warrants - see Room 641A, "SSL added and removed here", etc.
The current move to encrypt everything is a reaction to the realization that the balance that was thought to exist, does not, and political participation is not sufficient because the information is kept hidden, so no informed political discourse is possible.
I pointed out that it's easy to design cryptosystems to be unbreakably strong against all adversaries except governments, and indeed can be unbreakably strong against mass eavesdropping by governments, yet still provide access on a case by case basis. And in fact this is the outcome of all kinds of natural and widely adopted designs.
You're arguing that governments won't content themselves with such access. That's a different question entirely. I think many of them would and that we're heading in that direction, more or less, where mass decryption of TLS isn't done by most governments and the era of GCHQ/NSA style bulk wire tapping slowly fades away, but it doesn't matter to them much because they can still warrant the other end and ultimately that's what politicians feel safe campaigning on.
Is it? How? Because that's certainly not the default that you referred to.
Imagine you own a webmail company. You secure your SMTP relays with SMTP-TLS (let's pretend it works well) and your client connections with TLS again.
Now your users are safe from random creepy flatmates, criminals with wifi sniffers, your telco and even mass government surveillance. But, governments can still serve a warrant on you to get email in a targeted manner, assuming they have a working MLAT process.
All you did was apply ordinary encryption to an ordinary website and you have that middle ground between "unbreakable to everyone" and "totally useless".
But that's the point: we've seen that this balance doesn't exist, because if the service providers have access to the plaintext, the State will not contain itself to issuing case-by-case warrants - see Room 641A, "SSL added and removed here", etc.
The current move to encrypt everything is a reaction to the realization that the balance that was thought to exist, does not, and political participation is not sufficient because the information is kept hidden, so no informed political discourse is possible.
It's easy to confuse that with the name of a programme to reverse engineer and analyse Google internal traffic (which is presumably now over as all that traffic is encrypted), and I made that mistake myself, but I was corrected on HN no less by someone who is closer to the leaks than I am.
It wasn't something done with the knowledge of Google or Yahoo, as evidenced by the use of reverse engineering of the data formats.
Considering that governments are made up of people this would be quite a trick.
Regardless, even if it were so-- the objective would be to be unbreakable strong except to lawful and transparent actions of governments. The lawfulness of an action is undecidable by a cryptosystem. And we know that government frequently behave unlawfully.
Moreover, since cryptographic communications can be hidden very completely unless free access to computers and communication is almost completely suppressed; those who really want (and can afford) communications which are secure against government intrusion (lawful or otherwise) are able to obtain it. So the decision to purposefully weaken cryptosystems has the primary effect of amplifying unlawful intrusions by governments (and paries that steal the governments keys).
Client-to-server encryption with central message routing [..]
will be abused by the NSA and anyone else that can get their hands on access. And no amount of politicking is going to change that, as it hasn't changed anything about their blatant disregard of the law thus far. BTW, 'anyone else that can get their hands on access' will include foreign nations and criminals. [..] can easily be given a backdoor [..]
that magically does manage to stay out of the hands of foreign nations and criminals, where all other backdoors thus far have been discovered and abused?These arguments have a huge track record against them and I downvoted you for either acting wilfully ignorant.
Good timing, the day after your message-- there were dozens of them posted to the public with a suggestion more may go to the highest bidder.
https://www.washingtonpost.com/world/national-security/power...
“Without a doubt, they’re the keys to the kingdom,” said one former TAO employee, who spoke on the condition of anonymity to discuss sensitive internal operations. “The stuff you’re talking about would undermine the security of a lot of major government and corporate networks both here and abroad.” Said a second former TAO hacker who saw the file: “From what I saw, there was no doubt in my mind that it was legitimate.”
If the other example I gave wrt dual_ec drbg wasn't enough.
So not enough crypto to prevent absolute centralization of power by the institution with a monopoly on violence.
This isn't just governments either. Corporations do things like proxy HTTP traffic to cache pages and save on bandwidth (some ISPs do it too). By moving that to HTTPS traffic you are removing the ability to do this, and that gives them an incentive to do things like install root certificates for all their devices. Now your banking website has it's traffic sniffed as well, all in the name of caching the youtube videos that get distributed around the office.